Managed XDR

vtdl_jzwsq704 — malware analysis report

File info

Filename
vtdl_jzwsq704
File type
MS Windows shortcut, Item id list present, ctime=Sat Sep 14 10:42:36 2024, mtime=Sat Sep 14 10:42:36 2024, atime=Sat Sep 14 10:42:36 2024, length=0, window=hide
File size
1.1 KB
First seen
Last seen

Environment

win7/x86 en

Hashes

SHA1
ec22ec47bf1f3acea98693a33f791f9b02d537c9
SHA256
ff9f507ea65bab5197f6858e81dd382a6638a59029b8ef89e264b7b90e981274
MD5
7ebe8626d41450349ecd592ed13cc075

Signatures

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process